GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,849
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,585
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
1,585 advisories
Filter by severity
pageant: Out-of-bounds read / oversized allocation in `pageant` MemoryMap::read via a malicious Pageant agent (Windows)
Moderate
CVE-2026-102820
was published
for
pageant
(Rust)
Sep 30, 2026
Russh: Unbounded memory exhaustion via CHANNEL_OPEN flood during a client-stalled rekey
Moderate
CVE-2026-102821
was published
for
russh
(Rust)
Sep 30, 2026
russh: negotiating a MAC-requiring block cipher (CTR/CBC) with mac=none causes a slice-index-out-of-range panic
Low
CVE-2026-102822
was published
for
russh
(Rust)
Sep 30, 2026
russh: Client-side channel-scoped Handler callbacks fire for channel IDs the client never opened
High
CVE-2026-102823
was published
for
russh
(Rust)
Sep 30, 2026
Russh: Missing X25519 zero-point validation in hybrid ML-KEM key exchange
Moderate
CVE-2026-102824
was published
for
russh
(Rust)
Sep 30, 2026
Russh: Configured server auth-attempt cap is not enforced in the USERAUTH_REQUEST runtime path
Low
CVE-2026-102825
was published
for
russh
(Rust)
Sep 30, 2026
Ammonia: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Moderate
CVE-2026-102342
was published
for
ammonia
(Rust)
Sep 29, 2026
yara-x: Unvalidated deserialization in safe `Rules::deserialize` allows memory corruption and UB
Moderate
GHSA-2jx3-ff3v-j7jj
was published
for
yara-x
(Rust)
Sep 24, 2026
microsandbox: Secret values exposed in world-readable process arguments
Moderate
CVE-2026-61670
was published
for
microsandbox
(Rust)
Sep 22, 2026
Fulgur: Non-painting replaced elements amplify to thousands of blank PDF pages (denial of service)
High
CVE-2026-68537
was published
for
fulgur
(Rust)
Sep 17, 2026
Fulgur: Unbounded page slicing from attacker-controlled CSS height causes denial of service
High
CVE-2026-68523
was published
for
fulgur
(Rust)
Sep 17, 2026
RMCP: Custom HTTP headers leak to cross-origin redirect targets
Moderate
CVE-2026-64684
was published
for
rmcp
(Rust)
Sep 17, 2026
RMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP server transport leads to remote denial-of-service
High
CVE-2026-63128
was published
for
rmcp
(Rust)
Sep 16, 2026
RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery
High
CVE-2026-63127
was published
for
rmcp
(Rust)
Sep 16, 2026
libp2p-quic: Remote panic via certificate expiry race during QUIC handshake
High
CVE-2026-61544
was published
for
libp2p-quic
(Rust)
Sep 15, 2026
mistral.rs: Unbounded Remote Media Fetch and Video Frame Expansion DoS
High
GHSA-m3wp-48jr-vr4g
was published
for
mistralrs-server-core
(Rust)
Sep 10, 2026
mistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url
High
GHSA-wfgq-w7cq-qj7j
was published
for
mistralrs-server-core
(Rust)
Sep 10, 2026
gix-sec safe.directory protections absent for elevated administrators
Moderate
CVE-2025-24890
was published
for
gix-sec
(Rust)
Sep 9, 2026
SWC HTML minifier may allow script element breakout when minifying embedded JSON
Moderate
CVE-2026-72925
was published
for
@swc/html
(npm)
Sep 8, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
Moderate
CVE-2026-63733
was published
for
surrealdb-core
(Rust)
Sep 4, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
High
CVE-2026-63735
was published
for
surrealdb
(Rust)
Sep 4, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
CVE-2026-75911
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
High
CVE-2026-75858
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
CVE-2026-75912
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: SSRF bypass - TOCTOU on DNS failure for DNS pinning
Critical
CVE-2026-75856
was published
for
codewhale
(npm)
Sep 4, 2026
ProTip!
Advisories are also available from the
GraphQL API